[Git][security-tracker-team/security-tracker][master] Add new wolfssl issues
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Mon Jul 27 08:47:22 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
aab8079c by Salvatore Bonaccorso at 2026-07-27T09:47:03+02:00
Add new wolfssl issues
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -26247,19 +26247,24 @@ CVE-2026-11703 (Missing SNI/ALPN binding on stateful (session-ID) resumption, wh
[bookworm] - wolfssl <end-of-life> (EOL in bookworm LTS)
NOTE: https://github.com/wolfSSL/wolfssl/pull/10489 (v5.9.2-stable)
CVE-2026-11310 (X.509 trust-chain bypass in the OpenSSL compatibility certificate veri ...)
- TODO: check
+ - wolfssl 5.9.2-1
+ NOTE: https://github.com/wolfSSL/wolfssl/pull/10674 (v5.9.2-stable)
CVE-2026-10835 (The SALESmanago & Leadoo WordPress plugin before 3.11.3 does not prope ...)
NOT-FOR-US: WordPress plugin
CVE-2026-10823 (The YMC Filter WordPress plugin before 3.11.3 does not properly author ...)
NOT-FOR-US: WordPress plugin
CVE-2026-10592 (Certificates with wildcard DNS SANs (e.g. *.example.com) bypassed CA n ...)
- TODO: check
+ - wolfssl 5.9.2-1
+ NOTE: https://github.com/wolfSSL/wolfssl/pull/10549 (v5.9.2-stable)
CVE-2026-10512 (The X25519 x86_64 assembly implementation fails to clear the most sign ...)
- TODO: check
+ - wolfssl 5.9.2-1
+ NOTE: https://github.com/wolfSSL/wolfssl/pull/10536 (v5.9.2-stable)
CVE-2026-10098 (OCSP CertID serial-number length-confusion in wolfSSL_OCSP_resp_find_s ...)
- TODO: check
+ - wolfssl 5.9.2-1
+ NOTE: https://github.com/wolfSSL/wolfssl/pull/10554 (v5.9.2-stable)
CVE-2026-10097 (wolfSSL's AVX2-optimized ML-KEM implementation (mlkem_cmp_avx2) compar ...)
- TODO: check
+ - wolfssl 5.9.2-1
+ NOTE: https://github.com/wolfSSL/wolfssl/pull/10430 (v5.9.2-stable)
CVE-2025-71340 (picklescan through 0.0.26 fails to detect malicious pickle files that ...)
NOT-FOR-US: picklescan
CVE-2025-71338 (Flowise contains a path traversal vulnerability in the /api/v1/documen ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/aab8079c094364855b60bd871d0e673b8488bb5c
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/aab8079c094364855b60bd871d0e673b8488bb5c
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260727/a68c0133/attachment.htm>
More information about the debian-security-tracker-commits
mailing list